01Ledger 02Case Files 03Research 04Experience 05Skills 06Recognition 07Contact

Debasish Tripathy_

Debasish Tripathy/Agentic-AI Security Researcher·OffSec OSAI ·Bengaluru, India
Coordinated disclosure · active CVE-2026-64777 MSRC Acknowledged

Breaking
agentic AI.

Security Researcher/Prompt Injection·Tool-Permission Boundaries·Agent Sandboxing

I break the trust boundaries inside autonomous AI systems and libraries — then help vendors close them. Coordinated disclosures to Microsoft, Amazon, Apple, Cloudflare, Discourse and CERT-In, one assigned CVE, and a credited fix in Amazon's Kiro agent platform.

33+
Findings
8
Organizations
1
CVE assigned
4
Patents
asciify 94828569.jpeg → avatar.txt
rendered from source · colored · 84×51
00 / Summary at a glance

The disclosure record, by target.

Every item below was validated with a purpose-built reproduction — a real test harness or direct-call proof of concept, never a generic scanner. Several remain under coordinated-disclosure hold.

01 / Disclosure Ledger

Findings, filterable.

Class, impact, status and references — at advisory altitude. Tap any row to expand. No exploit payloads are published here.

02 / Case Files

Three that mattered most.

The highest-impact work — an agent-platform RCE chain, a runtime CVE, and an unauthenticated RCE review.

Chain · CriticalAmazon / Kiro

Cron-hijack → unattended RCE

kirodotdev/KiroCrew · PR #3836 · credited

An independent source review plus executed PoCs surfaced 7 findings in Amazon's Kiro agent platform. Chained, a scheduled-job hijack removed the human-approval step and ran at full owner privilege — the strongest map-to-real of indirect prompt injection and agent-sandbox escape. All seven fixed; reporter credited in the repo contributor list.

7/7
Fixed
2
Critical
2
Chains
Fixed · credited repo PR #3836
CVE · ModerateApple

Build-context path traversal

apple/container · CVE-2026-64777

Apple's Swift Linux-container runtime resolved build-context symlinks against the host during filesystem sync, so a malicious builder peer could read files outside the build context by name. CWE-22, CVSS 4.3. Fixed in container 1.2.0; a sibling advisory covers the same resolver's JSON walk mode.

4.3
CVSS 3.1
1.2.0
Fixed in
2
Advisories
Fixed · credited GHSA NVD
Review · CriticalCloudflare

Unauthenticated RCE surface

cloudflare/computer · H1 #3920538

A security review of Cloudflare's computer-use project produced six findings — three proven with PoCs: an unauthenticated WebSocket remote-code-execution path, a CSRF-drivable POST, and an SSRF. Submitted through HackerOne and under vendor assessment.

6
Findings
3
PoC-proven
RCE
Top class
Submitted vendor
03 / Research & Projects

Frameworks & shipped tools.

Featured · Local LLM inference

mirabilis

An 80B model at ~23 tok/s on a 6 GB laptop — by measuring the machine instead of trusting defaults. Profiles hardware, predicts a model's speed before download, then tunes by measurement: CUDA-backend detection, CPU-governor fixes, RAM budgeting, thread pinning, and MoE expert placement.

80B
params · 3B active
~23 tok/s
on 6 GB VRAM
2×
vs tuned Ollama 8B
04 / Experience

From research to production.

IT/ISC Security & Risk Compliance Intern
Philips Healthcare
Jul 2024 – Mar 2026 · Bengaluru
  • Established the AI Center of Excellence to standardize enterprise-wide AI governance.
  • Deployed an Automated SDLAN Security Check & Approval System across cross-functional teams.
  • Engineered a Certificate Lifecycle Management platform (ADCS, .NET, Python, AWS) at 100% uptime.
  • Built PKI-based ML-model certificate verification across 50+ FDA/CE-regulated device types.
AI CoEPKI.NETAWSGovernance
Machine Learning Engineer
MedDBot
Jun 2025 – Jan 2026 · Remote
  • Offline LLaMA 3.1-8B medical prescription: 97% accuracy, sub-500ms CPU latency, zero exfiltration.
  • Real-time anomaly detection for 200+ IoT devices: 94% precision (Isolation Forest + LSTM).
  • Cut inference cost 4× via INT8 quantisation at 98.5% output quality.
LLaMA 3.1INT8Edge ML
AI Safety Researcher — Trusted Tester
Google Labs
Aug 2024 – Jan 2025 · Remote
  • Prompt injection in Imagen 3 — contributed to a production safety release.
  • Automated adversarial testing: 500+ attack vectors, 8 unknown failure modes.
  • Open-source evaluation toolkit with 200+ GitHub stars.
Adversarial MLRed TeamingGenAI
Machine Learning Engineer
Genie AI, Inc.
Apr 2024 – Jun 2025 · Remote
  • Healthcare RAG chatbot: 89% query satisfaction across 5K+ conversations.
  • Thermal fire detection on Raspberry Pi 4: 95% accuracy at 15 FPS.
  • Cut deployment footprint 75% via structured pruning.
RAGTFLiteEdge ML
ML Research Intern — Firefly Team
Adobe Inc.
Nov 2023 – Dec 2023 · Bengaluru
  • Curated 100K+ image-text pairs; CLIP filtering improved semantic alignment by 23%.
  • Automated quality assessment — reduced manual curation by 60%.
CLIPPyTorch
05 / Technical Stack

The full toolkit.

Languages

PythonC++SQLBashJavaScriptSwiftGo

AI / ML

PyTorchTensorFlowJAXHugging FaceONNXCoreMLllama.cpp

Agentic-AI Security

Prompt InjectionTool-Permission BypassAgent SandboxingRed TeamingMCP Auditing

AppSec & Offensive

RCESSRFCSRFAuth BypassCWE-22 / Path TraversalBurp Suite

Cloud & MLOps

AWS SageMakerLambdaAzure MLDockerKubernetesMLflow

GenAI & LLM

RAGLangChainAdversarial MLQuantizationMoE Inference

Data & Infra

PostgreSQLRedisPineconeWeaviateFastAPI

Cryptography

ML-DSA / ML-KEMFROSTBLAKE3PKISHA-256

Responsible AI

SHAP / LIMEBias AuditingFDA/CEAI Governance
06 / Recognition & IP

Credited, on the record.

🏅

Microsoft Researcher Recognition

Special mention · 2nd consecutive year

🛡️

MSRC AI Safety Acknowledgments

Case 103869 · Feature Bypass, fixed

🧑‍💻

Amazon Kiro contributor list

Credited · PR #6923 · debasishtripathy13

🌏

BlueHat Asia 2026 · Singapore

Met the PyRIT team, Rehberger & E. Lim

🏛️

CERT-In coordinated disclosures

ISRO · IISc · DRDO — up to CVSS 9.9

📄

Publications

PHANTOM 2025 · SL Metrics · Vastu CV (IJAC)

Patents & Copyright
IN 202541045118

Vastumeter — Vastu Analysis System

IN 202441086519

Fashion Assessment System — AI/CV

IN 202541087250

Smart Neck Accessory — IoT Device

© 37205/2024

Cipher Decryption Algorithm

Competitions & Hackathons
🥇

Schneider Electric CTF

1st · 2024

🏆

Microsoft AI Odyssey India

Winner · 2024

🏆

Autodesk EduHack

Winner · 2024

🥈

PwC Firecrest Hackathon

2nd · 2025

🥉

Pine Labs AWS Playground

3rd · SentinelPay · 2026

🥇

Coder Army System Design

1st · 2024

07 / Education

Academic foundation.

B.Tech, Computer Science & Engineering
Manipal Institute of Technology, Bengaluru
Specialisation: Cybersecurity · Class of 2026
8.22CGPA / 10.0

Oracle Cloud Data Science Professional

ID 102993280
Nov 2025

Oracle Cloud AI Foundations Associate

Oct 2025

Cisco CCNA Enterprise Security

Jun 2025

OffSec AI Red Teamer (OSAI)

AI-300 · In progress
OffSec
Available · open to relocation

Let's harden
the agents.

AI red-teaming, agent-security, LLM-library hardening, or a coordinated disclosure — I respond promptly.